If you cannot find information about a compliance topic, please contact us for free support.
-
Policies & Procedures
- How to Submit Your SPRS Score: PIEE Step-by-Step Guide [2026 Update]
- CMMC Policies and Procedures: What Documentation You Need
- How to Write a System Security Plan: The Owner's Guide to the One Document That Gates Everything
- Creating a Plan of Action and Milestones for CMMC
- Documenting Evidence for CMMC Assessment
-
SPRS & Self-Assessment
-
CMMC Fundamentals
-
Contract Clauses & Flowdown
- DFARS and FAR Cybersecurity Clauses: What Each One Actually Requires
- What DFARS 252.204-7012 Requires, in Plain English
- DFARS 252.204-7019 vs 7020 vs 7021: What Each Clause Triggers
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
- DFARS flowdown requirements: Which Clauses You Must Pass to Your Subcontractors
- Flowdown: Which Clauses You Must Pass to Your Subcontractors
- Who Is Exempt from CMMC, and Why "We Only Make Parts" Usually Isn't
- What to Do When a DFARS Clause Appears in a Contract You Already Signed
- FAR 52.204-21 and FCI: The 15 Basic Safeguarding Requirements
-
Trigger Events & Urgent Situations
- Cybersecurity Questionnaire From Your Prime? Do This
- CUI Marked Drawings You Were Not Expecting? Do This
- Expired SPRS Score and a Bid Due? Fix It This Week
- Dropped Without CMMC? What a Prime Can Actually Do
- 90 Days to CMMC Compliance: What Is Really Possible
- DFARS 7021 Clause Found After Award? Read This First
- CMMC Compliant MSP? How to Verify What Yours Claims
- CUI in Commercial Microsoft 365: What to Do Now
- CMMC Level 2 Certification an RFP Wants? Bid Anyway
- CMMC Trigger Events: A Triage Guide for Contractors
-
CMMC Levels & Requirements
-
The 14 Control Families
- Access Control (AC)
- Awareness and Training (AT)
- Audit and Accountability (AU)
- Configuration Management (CM)
- Identification and Authentication (IA)
- CMMC Incident Response (IR)
- Maintenance (MA)
- Media Protection (MP)
- Personnel Security (PS)
- Physical Protection (PE)
- Risk Assessment (RA)
- Security Assessment (CA)
- System and Communications Protection (SC)
- System and Information Integrity (SI)
-
Implementation Roadmaps
-
Industry-Specific Guides
-
CMMC Documentation & Evidence
-
CMMC Costs & Budgeting
-
Technology & Tools
-
CMMC Training & Awareness
-
Supply Chain & Third-Party Risk
-
Incident Response & Breach Reporting
-
Common Mistakes & Failures
-
Advanced Topics & Level 2
-
Updates & Regulatory Changes
-
Artificial Intelligence (AI)
-
Comparisons & Alternatives
- GCC High vs GCC vs Commercial Microsoft 365 for CUI
- CMMC Compliance Options: Enclave, Environment or Service
- Enclave vs Full Remediation: Which CMMC Path Fits
- PreVeil vs GCC High for Small Defense Contractors
- CMMC Platform vs Consultant vs Doing It In House
- RPO vs C3PAO vs Consultant: Who Does What in CMMC
- CMMC Compliance Software for Small Manufacturers
- Azure Government vs AWS GovCloud for CUI Workloads
- Virtual Desktop Enclave vs Managed Laptops for CUI
- Free NIST 800-171 Tools vs Paid Platforms: The Gaps
- Build vs Buy Enclave: What In House Actually Costs
Free NIST 800-171 Tools vs Paid Platforms: The Gaps
The free NIST 800-171 tools published by the government are better than the market wants you to know, and they stop working at a point the market rarely explains. Both halves of that sentence are worth money to a small manufacturer trying to decide whether to spend anything at all.
What follows is what exists, what each one gives you, and the five specific places where the free route stops. This page is part of How to Compare CMMC Compliance Options: Enclave, Full Environment, or Managed Service.
The free NIST 800-171 tools the government actually publishes
| Resource | What it gives you | Condition |
|---|---|---|
| CMMC Level 2 Scoping Guide | The asset categories and the rules that determine how small your assessment boundary can legitimately be | Current. This is the highest value free document in existence and most contractors have never opened it |
| CMMC Level 2 Assessment Guide | The actual assessment objectives an assessor works through | Current |
| DoD Assessment Methodology | The exact scoring algorithm, with the weightings, that produces your SPRS score | Current and authoritative for scoring |
| Project Spectrum | Free readiness checks, training and help developing a plan, run by the Department’s small business programme | Aimed at small and medium contractors rather than large primes |
| CISA CSET | A free assessment tool you install and run locally, which matters when the answers describe controlled systems | Local install and maintenance. Confirm the modules it ships before relying on it |
| NIST Handbook 162 | A plain language self assessment workbook written for small manufacturers | Published in 2017 against an older revision. Useful for teaching, not as a current artifact |
| DoD guidance on reviewing System Security Plans | How the government reads your plan and your unimplemented requirements | Genuinely useful and almost never cited |
If you read only one item on that list, read the scoping guide. Scope is the largest cost lever in the entire programme and the rules governing it are published free.
The version trap, and it is the dangerous one
This catches careful people, so slow down here.
NIST published Revision 3 of SP 800-171 in May 2024 and withdrew Revision 2 at the same time. The current assessment procedures document is likewise Revision 3. Meanwhile the Department contracts to Revision 2, and the July 2026 suspension notice named Revision 2 explicitly.
So the newest document on the NIST website is not the standard you are assessed against. A contractor who assembles a free stack, downloads the latest revision and works diligently through it can end up assessed against the wrong baseline having done everything right. Anchor to Revision 2 until the Department says otherwise, and check the revision on every document before you use it.
Where the free NIST 800-171 tools genuinely stop
Five gaps, in the order they tend to bite.
No control inheritance. This is the biggest one and it is structural. No free document gives controlled information a compliant place to live. A government tenant or an enclave lets you inherit a meaningful set of technical controls; free guidance lets you inherit nothing. You will build and operate every control yourself. The free tools tell you what is required, and then you are on your own to provide it.
No evidence collection. Every free tool is a point in time questionnaire. Commercial platforms run automated tests continuously and gather artifacts. With the free stack you assert, then manually collect screenshots and exports across hundreds of assessment objectives. That manual gathering is where small teams drown, and it is recurring rather than one time.
No documentation output. Free tools help you assess. They do not produce a defensible System Security Plan, a policy set and a Plan of Action and Milestones. Writing that from nothing is realistically weeks of skilled labor, which is precisely why document sets sell for between roughly $5,200 and $25,583. How to Write a CMMC System Security Plan covers the structure if you take it on yourself.
No help with provider evidence. If you use a cloud provider on an equivalency rather than an authorization, the responsibility for validating their body of evidence and producing the customer responsibility matrix falls on you. No free tool produces or checks that.
No judgement, and judgement is where the money is. The scoping guide is free to read and genuinely hard to apply. Scoped too broadly and you pay to secure everything. Too narrowly and you fail. The market price for that judgement is visible in published gap assessments around $21,200 and readiness reviews around $9,200, and that price exists because the free documents supply rules rather than decisions.
When the free stack is the right answer
More often than the market admits, and more often in 2026 than in 2025.
If your controlled footprint is genuinely small, if you have a capable person with protected hours, and if leadership will make the scoping decision quickly, then the scoping guide to shrink the boundary, the assessment guide for the objectives, the methodology for the score, SPRS to submit and Project Spectrum for help is a complete and legitimate path to a defensible self assessment. What it costs is time and judgement rather than cash.
Two things make that trade better now than it was. Third party certification is suspended as a condition of award, so the pressure to buy speed has eased. And the obligations that remain, DFARS 252.204-7012, the 110 requirements, the SPRS score and the annual affirmation, are exactly the ones the free material addresses well.
Where it stops being the right answer is the moment you need a compliant environment. No amount of free documentation substitutes for a place to put the data, which is a purchase. That decision is covered in enclave vs full remediation, and the products in CMMC compliance software for small manufacturers.
A stack of free NIST 800-171 tools that works, in order
- Read the Level 2 Scoping Guide first. Decide your boundary before you assess anything, because assessing an unbounded environment is how projects stall.
- Work the Level 2 Assessment Guide objectives against that boundary. These are the objectives an assessor uses, so there is no better checklist at any price.
- Score with the Department’s methodology, using the published weightings rather than a vendor’s interpretation.
- Write the plan and the Plan of Action and Milestones yourself. Slow, and the knowledge stays in the building.
- Use Project Spectrum for the questions you cannot resolve internally. It exists for exactly this and costs nothing.
- Submit in SPRS and get the affirmation signed. Note that SPRS stores results and does not perform the assessment, and that you need the appropriate role provisioned first, which takes time nobody budgets for.
Frequently asked
Questions about this topic
Can we get compliant using only free NIST 800-171 tools?
Which revision of NIST SP 800-171 should we use?
Is NIST Handbook 162 still usable?
What is the single most valuable free document?
Do free tools produce our System Security Plan?
Does the Phase 2 suspension make the free route more viable?
Keep reading
More in Comparisons & Alternatives
- Azure Government vs AWS GovCloud for CUI Workloads →
- Build vs Buy Enclave: What In House Actually Costs →
- CMMC Compliance Options: Enclave, Environment or Service →
- CMMC Compliance Software for Small Manufacturers →
- CMMC Platform vs Consultant vs Doing It In House →
- Enclave vs Full Remediation: Which CMMC Path Fits →
- GCC High vs GCC vs Commercial Microsoft 365 for CUI →
- PreVeil vs GCC High for Small Defense Contractors →
- RPO vs C3PAO vs Consultant: Who Does What in CMMC →
- Virtual Desktop Enclave vs Managed Laptops for CUI →
Free tools
Get to an honest number faster
You will run this more than once: after any material change to your environment, and again before every annual affirmation. Both are free, and both are yours to keep.
Neither is a certified assessment, and neither pretends to be.
Official sources
The audit is gone. The liability isn't.
Greypike runs the environment your CUI lives in and owns the compliance outcome that proves it's protected. If you are not certain your environment supports the score sitting in SPRS next to your CAGE code, that is the conversation to have.
Talk to Greypike about SPRS Attestation AssuranceGreypike Inc.
SBA-certified Veteran-Owned Small Business
Cyber AB Registered Practitioner (RP) and Registered Practitioner Advanced (RPA) on staff
CAGE 9WVS6 · UEI N6CJNGDARFM5